Пример #1
0
 def test_OpenCurrentUser(self):
     dce, rpctransport, phKey = self.connect()
     request = rrp.OpenCurrentUser()
     request['ServerName'] = NULL
     request['samDesired'] = MAXIMUM_ALLOWED
     resp = dce.request(request)
     resp.dump()
Пример #2
0
    def test_BaseRegSaveKey(self):
        dce, rpctransport, phKey = self.connect()

        request = rrp.OpenCurrentUser()
        request['ServerName'] = NULL
        request['samDesired'] = MAXIMUM_ALLOWED
        resp = dce.request(request)
        resp.dump()

        request = rrp.BaseRegSaveKey()
        request['hKey'] = resp['phKey']
        request['lpFile'] = 'BETUSFILE2\x00'
        request['pSecurityAttributes'] = NULL
        resp = dce.request(request)
        resp.dump()
        # I gotta remove the file now :s
        smb = rpctransport.get_smb_connection()
        smb.deleteFile('ADMIN$', 'System32\\BETUSFILE2')